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Switching control, servomechanism, and H 2 control theory are used to provide a practical 
and easy-to-implement solution for the actuator jam problem. A jammed actuator not only 
causes a reduction of control authority, but also creates a persistent disturbance with 
uncertain amplitude. The longitudinal dynamics model of the NASA GTM UAV is employed 
to demonstrate that a single fixed reconfigured controller design based on the proposed 
approach is capable of accommodating an elevator jam failure with arbitrary jam position 
as long as the thrust control has enough control authority. This paper is a first step towards 
solving a more comprehensive in-flight loss-of-control accident prevention problem that 
involves multiple actuator failures, structure damages, unanticipated faults, and nonlinear 
upset regime recovery, etc. 


Nomenclature 


x(t) = [V a q 6 h Pf 
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state vector 

control input vector 

velocity, ft/s 

angle of attack, deg 

pitch rate, deg/s 

pitch angle, deg 

altitude, ft 

power level, percent 

thrust control, between 0 and 1 

elevator control, deg 


I. Introduction 

I n the past ten years, 59% of the fatal airliner aircraft accidents were caused by loss-of-control in flight and another 
33% by controlled flight into terrain 1 . The accident reports published by NTSB (National Transportation Safety 
Board) 2 have revealed that most in-flight loss-of-control accidents were triggered by faults including 
subsystem/component failures, external hazards, and human errors. With hindsight, it is easy to say that most of 
these accidents could have been prevented if the maintenance were performed better to avoid component failures, or 
if the aircraft had not entered the hazardous region, or if the flight crews had not made mistakes, etc. It is true that 
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prevention is the best medicine and these preventive measures should continue to be enhanced. However, just like 
the inability of preventive medicine to stop all diseases, it is impossible to eliminate all the faults that may threaten 
flight safety. Hence, it is necessary to ensure that the aircraft are adequately equipped and crew members are well 
trained to deal with all possible in-flight faults, minimize their adverse effect, and to be able to steer the aircraft 
away from possible upset regimes where the aircraft may lose control or become unstable. 

On January 31, 2000, Alaska Airlines Flight 261 (McDonnell Douglas MD-83) dived with nose down into the 
Pacific Ocean about 60 miles west of Los Angeles because of a jammed horizontal stabilizer 3 . The 2 pilots, 3 cabin 
crewmembers, and 83 passengers on board were killed, and the airplane was destroyed by impact forces. The jam 
was later determined to be a direct result of the in-flight failure of the acme nut threads in the horizontal stabilizer 
trim system jackscrew assembly. Malfunction or jam of aircraft control surfaces like elevators, rudders, ailerons can 
be very dangerous since these faults not only result in the reduction of control authority, but they also impose 
persistent disturbances on the aircraft. The jammed control surface position can be anywhere in the operational 
range and is not known a priori. If the jam position is not too far away from the trim condition, the remaining control 
authority may be enough to be utilized to maintain a safe flight. However, if the jam occurs near an extreme position, 
the available control authority may not be able to offset the effect of the persistent disturbance caused by the jam. 
The first fault the Flight 261 crew members encountered was a horizontal stabilizer jam at 0.4°, which was near the 
trim condition. This fault was not severe and the pilots were able to keep the aircraft aloft at 31,050 feet preparing 
for an emergency landing. But about twenty minutes later, the horizontal stabilizer was moved by an excessive force 
with huge noise from 0.4° to a new jam position, 2.5° airplane nose down, and the airplane began to pitch nose 
down, starting a dive. Things got worse after that - pilots lost control of the pitch axis, and the aircraft crashed into 
the ocean 11 minutes and 37 seconds later. 

The actuators for the aircraft control surfaces, elevator, rudder, and ailerons usually are electromechanical or 
hydraulic systems and the most common malfunctions for these systems are mechanical or hydraulic jams 4 that 
render the control surfaces useless. Furthermore, the jams create harmful persistent disturbances that would force the 
aircraft to move in undesired directions. If the jam occurs at the rudder, the aircraft will continue to change heading 
and make circles. A jam at the ailerons will cause an unwanted roll or even a spin, and a jam at the elevator may 
lead to a dive and crash. Although jam of a control surface is potentially fatal, the effect of the fault can be 
neutralized if the aircraft is equipped with enough diversified redundancy and adequate accommodation actions are 
taken in time. 

It is well known that the controller that provides a desired performance for the nominal system in general cannot 
continue to deliver that level of performance when some actuator fails. The actuator failure may result in an 
unacceptable performance or even cause the aircraft to drift into dangerous nonlinear upset flight regimes where the 
aircraft may lose controllability and become unstable. A widely used approach for the actuator failure problem in 
early times was the Pseudo-inverse Method or the Mixer Approach 5 " 8 , which was used to redesign the controller for 
the system with actuator failure so that the redesigned closed-loop characteristic matrix approximates that of the 
original closed-loop system. Usually these two matrices are not the same. Even if they are identical, the redesigned 
system may still exhibit poor performance since the system structure and dynamics with actuator failure may be 
significantly different from the original one. For example, a jammed actuator not only cannot be used as a control 
input anymore but also becomes a persistent disturbance input to the new system. In other words, the systems before 
and after the occurrence of the actuator failure are very different: one without and the other with a persistent 
disturbance input. In the Gao and Antsaklis’ paper 9 , they pointed out that the Pseudo-inverse Method does not 
guarantee the stability of the redesigned closed-loop system. Consequently, they proposed a modified pseudo- 
inverse algorithm to resolve the stability issue. However, the other drawbacks mentioned above still remain 
unresolved. 

Adaptive control approaches 10 " 11 also can be employed to address actuator failures. These approaches usually 
assume limited or no knowledge of the system parameters. How many actuators have failed and at what fixed 
positions are also assumed unknown. These approaches require continuous complicated online update of the 
parameters in the controller that may take too long and not be able to accommodate the failure in time. Recently, J.P. 
Hespanha, D. Liberzon, A.S. Morse, B.O. Anderson, and T. Brinsmead 13 " 14 discussed the limitations of adaptive 
control, and proposed to overcome these limitations by means of multiple models and logic-based switching. In our 
opinion, a comprehensive feasible solution needs to be able to accommodate all anticipated major failures and 
unforeseeable minor ones, and the objective can be achieved by using hybrid, nonlinear, robust, adaptive, and 
servomechanism control technologies. 

We first presented the idea of using multiple switching controllers and employing the servomechanism 15 " 19 and 
H 1 control theory" " to address the actuator jam problem in Chang, Bajpai, and Kwatny" , and later extended the 
scope to more general issues 23 " 27 including nonlinearities, asymmetric failures, recoverability, diversified 
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redundancy, etc. In our proposed approach, we considered the nominal and all foreseeable actuator jam scenarios 
and their associated plants, G 0 , G, , ... G, . In addition to the optimal nominal controller K 0 for G 0 , we 
specifically designed a best possible reconfigured controller K t for each G, . A switching mechanism will determine 
which controller to engage according to the actuator jam scenario. We designed the reconfigured controllers based 
on the servomechanism and H 1 control approach that allows a single fixed controller to neutralize the effect of the 
persistent disturbances in spite of jam positions. The ability to handle arbitrary jam positions using just one fixed 
controller greatly simplifies the design and implementation. Furthermore, the number of the actuator jam scenarios 
to be considered usually is not too many. For instance, if an aircraft has three control surface actuators: elevator, 
rudder, and ailerons and they may jam at any possible position, then there are only seven possible scenarios and only 
seven reconfigured controllers are required. 

To successfully implement the hybrid control approach that relies on multiple pre-designed controllers and 
logical-based switching, several critical issues still need to be addressed. Usually there is a time delay between the 
occurrence of a failure and the accommodation control action taken to address the failure. If the delay is too long, 
the impaired aircraft may have drifted to a highly nonlinear upset regime before the accommodation control action 
can be effective. The controller switching transition can be problematic, especially in nonlinear flight regimes. 

In this paper, we will investigate how an actuator jam affects the performance of the NASA generic transport 
model (GTM) aircraft 28 " 29 , a twin-turbine unmanned aerial vehicle (UAV). The UAV is 5.5% dynamically scaled to 
realistically simulate characteristics of a full-scale large civil transport jet aircraft. We will also apply our actuator 
jam neutralization approach to the GTM aircraft based on hybrid control (multiple controllers with switching), 
servomechanism, and H 1 optimal control techniques. For the sake of simplicity and clarity of presentation, in this 
paper we will focus on one actuator jam scenario: elevator jam, which is a first step towards solving a more 
comprehensive in-flight loss-of-control accident prevention problem that involves multiple actuator failures, 
structure damages, unanticipated faults, and nonlinear upset regime recovery, etc. 

The rest of the paper is organized as follows. In Section II, we briefly introduce the linearized longitudinal flight 
dynamics model of the GTM aircraft at a trim condition and examine how the control inputs, thrust and elevator 
position, would affect the state variables: the speed, angle of attack, pitch angle, pitch rate, and altitude of the system. 
The problem formulations for finding the nominal and reconfigured controllers that would provide optimal 
performance before and after the elevator jam failure will be also presented in the section. Solutions to these two 
formulated problems and detailed procedures for constructing these two controllers will be given in Section III. In 
Section IV, several simulation results will be presented to show the inability of the nominal controller to perform 
altitude tracking or even maintain stability after an elevator jam occurs, and to show the ability of the reconfigured 
controller to provide optimal performance for the impaired system despite the jam position as long as the remaining 
effective actuator, the engine thrust, has enough control authority. The proposed hybrid, servomechanism and 
H 1 control approach can be extended to the cases involving multiple actuator failures, structure damage failures, 
subsystem failures, etc. using just a limited number of reconfigured controllers. Furthermore, these reconfigured 
controllers can be also nonlinear, robust, and adaptive to that the control system also can handle nonlinearities, plant 
uncertainties, uncertain disturbances, and parameter dependencies, etc. 

II. Longitudinal Flight Dynamics of the GTM Aircraft and Problem Formulation 

In order to study the flight dynamics and behavior of the civil transport jet aircraft under adverse flight 
conditions and to search for means to prevent in-flight loss-of-control accidents, NASA has built a generic transport 
model (GTM) aircraft, a twin-turbine unmanned aerial vehicle (UAV), as a test bed. The UAV is 5.5% dynamically 
scaled to realistically simulate characteristics of a full-scale large civil transport jet aircraft. In this paper, we will 
investigate how an elevator jam would affect the flight of the GTM aircraft and apply our actuator jam neutralization 
approach to minimize the effect of the elevator failure. 

Longitudinal Flight Dynamics of the GTM Aircraft 

A trim condition of the aircraft under consideration is shown as follows: 

V = 126.67 ft/ s, a = 4.71°, /? = - 0.04°, 0 = 0°, 0 = 4.71°, y/ = 0‘, 

p = 0°/s, q = 0°/s, r = 0° / s, x e = 0 ft, y e =0ft, h = 600ft, P = 15.06%, (1) 

= 0.15, u Se = 1.24°, u Sa = 0.06°, u Sr = -0.06°. 
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where V is the velocity, a the angle of attack, ft the sideslip angle; (j>, 0, and t// are the roll, pitch, and yaw 


angles respectively; p, q, and r are roll rate, pitch rate, and yaw rate respectively; x e , y e , and h represent the 
position of the vehicle on the earth frame in which h is the altitude, and P represents the power level measured in 
percentage. The thrust control input u T is between 0 and 1, where 1 represents the maximum available thrust; 
u Se , u Sa , and u Sr are the elevator, aileron, and rudder control input angles, respectively. 

The linearized longitudinal flight dynamics model of the GTM aircraft at the above trim condition is given in 
the following, 

x(t) = Ax(t) + B^uf) (2a) 

where the state vector is x(t) = [V a q 6 h P] T , the control input vector u(t)=[u T u Se \ , and 
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It is easy to check out that the system is controllable when both u T and u Se are available. It also can be shown 
that the system is still controllable with the thrust u T alone as control input. From the time-domain open-loop 


system simulation in the following, we can see that either the thrust u T or the elevator position u Se is able to 
effectively affect the pitch, angle of attack, velocity, and altitude of the aircraft. In Figure 1, it is assumed that 
u T = 0 and u Se jumps from 0 to 1° at t=0, i.e., the thrust remains the same at the trim level, and the elevator control 


input u Se moves up from its trim position by 1 deg. The left of Figure 1 shows that the velocity increases by 25 ft/s 


and the altitude drops by almost 90 ft at t=10s, while the power level remains the same as the trim condition. The 
changes of pitch rate, pitch angle, and angle of attack as a function of time shown in the right of Figure 1. In Figure 
2, we assume u Se = 0 and u r jumps from 0 to 0.05 at t=0, i.e., the elevator position remains the same as in the trim 
condition, and the thrust control increases by 0.05 to 20% of its maximum power. The time response curves in the 
left of Figure 2 show that the altitude rises up and the velocity slightly decreases. The right of Figure 2 shows the 
pitch angle is up by 0.05 deg while the angle of attack moves up just a little bit. 
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Figure 1. Time response of the open-loop system due to the inputs: u T = 0 and u gt . jumps from 0 to 1° at t=0. 



Figure 2. Time response of the open-loop system due to the inputs: u Se = 0 and u T jumps from 0 to 0.05 at t=0. 
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Problem Formulations for Finding the Nominal and Reconfigured Controllers 

The objective is to design two controllers, the nominal controller K 0 and the reconfigured controller K t , so that 
K 0 will normally work together with the nominal plant, but when an elevator jam occurs, K x will step in and 
replace K 0 to provide a best possible performance for the impaired plant. 


The Nominal Controller K n 



The nominal controller K 0 will be designed to stabilize the nominal closed-loop system, to fly the aircraft at a 
desired altitude, and to minimize the transient tracking errors subject to control input constraints. This nominal 
controller design problem can be formulated as a servomechanism and H 1 optimization control problem as follows. 

1 ^ 

' z=\ 


u = 


Figure 3. Nominal generalized plant G 0 and the associated controller K 0 . 

Consider the block diagram shown in Figure 3, in which the nominal generalized plant G 0 can be described by 
the following equations. 


x(t) = Ax(t)+V d d(t) + B 2 u(t) 


z i (0 


'c,.' 


'D nu ~ 


0 




x(t) + 


r a (0 + 


3(0 


0 


0 




y(t) = C 2 x(t) + n(t ) 
and the tracking signal r a (t) satisfies 

r a (t) = z o r a(t) with Z o=° 


(3a) 

(3b) 

(3c) 

(3d) 


In Eq. (3a), x(t) = [V a q 0 h P] T is the state vector, u(t) = \u T u d - e ]' is the control input vector, and the 
matrices A and B-, are given in Eq. (2b). In Eq. (3b), z, is the error to be minimized, z 2 represents control-input 
constraints, and r a (t) stands for a desired altitude which is a step function with arbitrary amplitude. Since the error 
here is defined as the difference of r a (t) and h{t ) , we have 

C lu = [0 0 0 0 -1 0] , and D Uu = 1 (3e) 

The matrix C, in Eq. (3c) is assumed to be an identity matrix. Without loss of generality, dU) and n(t) are 
assumed white noises with the following covariances, 


E{dd T ) = I, E(nn T ) = V, E{dn T ) = 0 (3f) 

D Vcl will be chosen in the design process to satisfy the control input constraints, and V and V d will be determined 
based on the measurement noises and disturbances. 

Now the problem is to find a controller K 0 so that the closed-loop system is stable, the steady-state tracking 
error is zero, i.e., 


limZ[(t) = 0. 

t — >oo 

and the following performance index 


J - lim — E 


£ z T (t)z(t)dt 


is minimized. 


(4a) 

(4b) 
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The Reconfigured Controller K 1 

The problem formulation for finding the reconfigured controller K ] is similar to that for K 0 . K t will be 
designed to stabilize the impaired system with jammed elevator, to fly the aircraft at a desired altitude, to neutralize 
the effect of the persistent disturbance caused by the elevator jam, and to minimize the transient tracking errors 
subject to constraints on the remaining effective control inputs. This reconfigured controller design problem can also 
be formulated as a servomechanism and H 1 optimization control problem as follows. 


u 


8e 


r a 



Figure 4. The generalized plant G, with jammed elevator and the associated controller K x . 
Consider the block diagram shown in Figure 4 in which the generalized plant G, with elevator jammed at 
arbitrary position can be described by the following equations, 


x(t) = Ax(t ) + V d d(t) + [B 2e 0] 


z(t) = 


u Se (t) 0 
0 r a (t) 


+ B 2T u T ( t ) 


Z,(0 


■<v 

x(t) + 

"0 A !„/ 

W d>(0 

0 “ 

+ 

_Z 2 (0_ 


0 

0 0 

0 

r a(t)_ 



D, 


12 dj 


U T (t) 


(5a) 

(5b) 


y(t) = C 2 x(t ) + n(t) (5c) 

and the tracking signal r a (t) and the elevator jam position u ge (t) , which used to be a control input but now 
becomes an unwanted persistent disturbance, satisfy the following equations, 


f(t) = Z () rjt) with Z 0 = 0 
u Se (t) = Z e u Se (t) with Z e =0 


(5d) 

(5e) 


In Eq. (5a), x(t) = [V a q 0 h pj is the state vector, u T (t ) is the remaining effective control input vector, 
and the matrices A and B-, = [B 2T B le ] are given in Eq. (2b), in which B-, r and B 2r are the first and second 
columns of B 2 . In Eq. (5b), z, is the error to be minimized, z, reflects control-input constraints, and r, (7) stands 
for a desired altitude which is a step function with arbitrary amplitude. Since the error here is defined as the 
difference of r a (t ) and h(t) , we have 

c iuj = [o 0 0 0 -1 0] , and D Uuj =1 (5f) 

The matrix C, in Eq. (5c) is assumed to be an identity matrix. Without loss of generality, d(t) and n(t) are 
assumed white noises with the following covariances, 


E{dd T ) = /, E{nn) = V, E{dn) = 0 (5g) 

D nd , will be chosen in the design process to satisfy the control input constraints, and V and V d will be determined 
based on the measurement noises and disturbances. 

Now the problem is to find a controller K t so that the closed-loop system is stable, the steady-state tracking 
error is zero, i.e., 


limz,(t) = 0 (6a) 

t — >oo 

and the following performance index 
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(6b) 


J = lim— itTf z T (t)z(t)dt 
r-»® T |_ Jo 

is minimized. 

The solutions to the above two problems listed in Eqs. (4a&b) and (6a&b) and the design for the two controllers 
K 0 and K t will be given in the next section. 

III. Design of the Nominal and Reconfigured Controllers 

In this section we will solve the two controller design problems posed in Eqs. (4) and (6), respectively. The 
nominal controller K 0 is designed using both normally available control inputs: thrust u T and elevator actuator 
u Se to achieve stability, zero steady-state tracking error, and optimal H 2 performance for the nominal plant G 0 . The 
reconfigured controller AT, , on the other hand, is to be designed using just one control input, the thrust u T , under the 
adverse condition that the elevator is jammed and the jam position is unknown a priori. This reconfigured controller 
needs to stabilize the impaired system, to neutralize the effect of the persistent disturbance caused by the jammed 
elevator, to minimize the tracking error, and provide the best possible H 2 performance for the impaired plant G, . 

Design of the Nominal Controller K 0 

The structure of the nominal controller is shown in Figure 5. The observer is employed to optimally estimate the 
states of the plant, and use them for feedback. The servomechanism matrices W, and U are designed so that the 
system is able to track the reference signal r a it) and ensure zero steady-state tracking error. The state feedback gain 
matrix F is determined to stabilize the closed-loop system and optimize the //, performance of the system. 



Figure 5. Structure of the nominal controller K 0 . 


Determination of W and U for Steady-state Regulation 

The block diagram of the proposed regulator controller to accommodate the actuator failure is shown in Figure 
5. The condition for the existence of stabilizing controllers is that the system (A,B 1 ,C 2 ) is stabilizable and 
detectable. As long as the closed-loop system is internally stable, the steady-state regulation will take place if W and 


U are chosen so that the following equations are satisfied 18 19 , 

AW + B 2 U-WZ 0 = 0 (7a) 

C lu W + D nu =0 (7b) 

where the matrices A, B 2 , C lu , D Uu , and Z 0 are given in Eq. (2b), (3e) and (3d). A solution to these equations can 
be found as, 

W = [2.0825 xKT 4 -2.8561xl(T 7 0 -2.8561xl0“ 7 1 -5.8175xl(T 4 ] r (8a) 

U = |^— 5.8 1 75 x 10 6 0] r (8b) 


Observer Construction 

Since ( A,C 2 ) is detectable, a stable observer can be constructed as follows, 
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(9a) 


x(t ) = (A - LC 2 ) x(t) + B 2 u(t) + Ly(t) 
where the observer gain L is 

l = yc t 2 v-' 

and Y is the positive semi-definite stabilizing solution of the following algebraic Riccati equation, 
AY + YA T - YCl V 'C 2 Y + V d Vj = 0 
With V d = 10 2 / 6 and V = 10 _1< / 6 , we have the observer gain. 
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which places the observer poles at -124 ± j 73.3 , -102 ± y'20.7 , and -100 ± y'0.05 . 


Determination of the State Feedback Gain F 
Define 


e=c; , „c 1 „ 


and R = D nd D nd 


Then the state feedback gain matrix F can be computed as follows, 


F = -R l B 2 X 


where X is the positive semi-definite stabilizing solution of the following algebraic Riccati equation, 
A t X + XA - XB 2 R 'B{X + Q = 0 


With D nd chosen as 


A2 d ~ 


F = 


300 0 

0 10 _ 

we have the state feedback gain, 

"-.00322 .0975 -.00322 -.103 -.000835 -.000588“ 

.0645 -20.18 1.291 24.13 .09685 .01849 

which places the regulator poles at -3.13 ± 76 . 06 , -.045, -1, and -.453 ± y.548 . 


(9b) 

(9c) 


(9d) 


( 10 a) 

(10b) 

(10c) 


(lOd) 


Design of the Reconfigured Controller K t 

The structure of the reconfigured controller is shown in Figure 6 . Note that the number of available control 
inputs has reduced to one: thrust u T . Furthermore, the loss of the jammed elevator as a control authority does not 
mean it would simply disappear. The jammed elevator u Se is still there, but acts as a persistent disturbance that can 
be harmful to the aircraft. The extent of the effect of the jammed elevator varies as function of the jam position, 
which can be anywhere in the operating range and is not known a priori. The observer is constructed based on linear 
quadratic estimation to optimally estimate the states of the plant. The servomechanism matrices Wj , and U ■ are 
designed so that the system is able to neutralize the effect of the persistent disturbance caused by the jammed 
elevator at any position, and track the reference signal r ( t ) . The state feedback gain matrix F j is determined to 

stabilize the impaired system and optimize its If performance. 

Determination of W. and Uj for Steady-state Regulation 

The block diagram of the proposed regulator controller to accommodate the actuator failure is shown in Figure 
6 . The condition for the existence of stabilizing controllers is that the system ( A,B 1T ,C 2 ) is stabilizable and 
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detectable. As long as the closed-loop system is internally stable, the steady-state regulation will take place if W, 
and Uj are chosen so that the following equations are satisfied 18 19 , 


AW J+ [B 2e 0] + B 2t Uj - Wj 


Ze 0 

0 z n 


= 0 


(11a) 


c^Wj+l o Ai„y] = o (lib) 

where the matrices A, B 2e , B lr , C, , D n ■ , Z e , and Z 0 are given in Eq. (2b), (5a), (5f), (5d) and (5e). A solution to 
these equations can be found as, 

13.066 2.0825 xlO -4 


Wj = 


-.020967 -2.8561x10 7 
0 0 

-.020967 -2.8561xl0~ 7 
0 1 

-.82277 -5.8175xl0~ 4 

Uj =[-8.2277 xl0“ 3 -5.8175xl0~ 6 ] 


(12a) 


(12b) 



Observer Construction 

Since ( A,C 2 ) is detectable, a stable observer can be constructed as follows, 

x(t) = (A-LC 2 )x(t) + B 2T u T {t) + Ly(t) (13a) 

where the observer gain L is 

L = YC 2 V~' (13b) 

and Y is the positive semi-definite stabilizing solution of the following algebraic Riccati equation, 

AY + YA t - YC\ V~'C 2 Y + V d Vj = 0 (13c) 

With V d =10 ~ 2 / 6 and V = 10 ~ s / 6 , the observer gain L can be found the same as that shown in Eq. (9d), which 
places the observer poles at -124 ± y'73.3 , -102 ± y'20.7 , and -100 ± y'0.05 . 

Determination of the State Feedback Gain F 
Define 

Qj = C iuj C i uj and Rj =D\ 2ij D X2ij (14a) 

Then the state feedback gain matrix F can be computed as follows, 

F j =-R-'B T 2T X j (14b) 
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(14c) 


where X f is the positive semi-definite stabilizing solution of the following algebraic Riccati equation, 

A T X. +X i A-X i B 7T R~'B T „X r +Q, =0 

J J J J 11 J x-'J 

With D nd/ chosen as 300, we have found the state feedback gain, 

Fj = [-.01588 1.138 -.06195 -1.283 -.003338 -.00337] (14d) 

which places the regulator poles at -3.13 ± 76 . 06 , -.167, -1, and -.101 ± /.35 . 

IV, Simulations of Elevator Jam Failure Accommodations 

In Section III, we have designed a nominal controller K 0 and a reconfigured controller K x . K u is employed 
under normal circumstances, but when the elevator is jammed and ceases to function K t will replace K 0 to stabilize 
the impaired system and neutralize the persistent disturbance caused by the elevator jam. The simulations will 
include two parts. In Part 1, the GTM aircraft is assumed to initially fly at the trim condition and then the controller 
will follow a descent command to maneuver the aircraft to go down to the desired altitude. Three simulation cases 
are to be conducted for this descending maneuver. Case 1 is conducted with no actuator failure, and the nominal 
control K 0 will be expected to perform well. In Case 2, the simulation will be conducted with the assumption that 
the elevator actuator is jammed at 1 second during the altitude tracking process, but no action is taken to replace or 
modify K 0 to accommodate the failure. The response of the impaired system without failure accommodation is not 
expected to be satisfactory. In Case 3, the simulation will be similar to Case 2, the elevator actuator jammed at 1 

second, but a switching action will be activated to replace K 0 by the reconfigured controller K\ at 1.1 seconds. We 

are assuming here a 0. 1 second time delay in performing the switching. The time response of all the states and 
control inputs will be examined and checked out if the reconfigured controller works as desired. The three cases of 
Part 1 simulations will be repeated in Part 2 using the same nominal and reconfigured controllers, but this time the 
controller will follow an ascent command and the elevator jam will be assumed to occur at 1.5 seconds. The reason 
to have two different maneuver simulations is to show that the same fixed reconfigured controller K t is capable of 
accommodating elevator jam failures at any position as long as the remaining effective control input, engine thrust 
u T has enough control authority. 

Part 1: Descending Maneuver of the GTM Aircraft with Altitude Tracking Controller 

The GTM aircraft is assumed flying at the trim condition at t=0, when it receives a command to descend 50 feet 
from its current altitude, 600 feet, the trim condition. To follow the command, the nominal controller K 0 will start 
to maneuver the aircraft to fly toward the desired altitude via the control of the thrust u, and the elevator u Se . Three 
simulation cases for this descending maneuver will be considered in the following. 

Case 1: No failure occurs and the nominal controller K 0 will continue to finish the control of descending. 

The simulation results for Case 1 are shown in Figure 7. The bottom left and right figures reveal how the elevator 
and thrust were controlled to affect the pitch rate, pitch angle and the angle of attack (in the upper right figure) 
that in turn would determine the altitude and velocity shown in the upper left figure. It can be seen that the altitude 
h went down from 0 (the trim altitude 600 ft) to undershoot and overshoot a little bit before it settled at -50 ft 
(actual altitude = 550 ft) as desired around t=10s, while the velocity V increased from 0 (the trim velocity 127 ft/s) 
to 12 ft/s at t=5s and then down to 5 ft/s at t=20s. In the altitude tracking process, the thrust drop was less than 4 
percent and the elevator operating range was between 4.5 deg and -0.5 deg. 

Case 2: Elevator jam occurs at t=ls, but no failure accommodation action is taken. 

The simulation results for Case 2 are shown in Figure 8 . The aircraft behaved exactly the same as Case 1 before 
the elevator failed. To follow the descent command, the nominal controller K 0 dictated the elevator to jump up to 
4.8 deg position and then to reverse to decrease the elevator angle. At the 1 second, the elevator failed and 
jammed at the 1.5 deg position. As shown in the bottom left figure, the elevator angle u Se continued to stay at the 
1.5 deg position throughout the simulation. This uncontrollable elevator position rendered the elevator control 
signal from the nominal controller K 0 useless, and produced an unwanted persistent rotational moment to cause 
the aircraft to pitch down. It can be seen in the bottom right figure that the inadequate controller K n straggled to 
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use the only available control input, the engine thrust u T , to prevent the aircraft from further pitching down. 
However, it only causes the aircraft to pitch up and down with large amplitude, oscillating between -150 ft and - 
50 ft, and there was no sign of settling towards the desired altitude as shown in the upper left and right figures of 
Figure 8. 





Figure 7. Time response for Part 1, Case 1. 



Case 3: Elevator jam occurs at t=ls, and the reconfigured controller K t steps in to replace K 0 at t=l.ls. 

The simulation results for Case 3 are shown in Figure 9. The aircraft behaved the same as Cases 1 and 2 before 
the elevator failed. At 1 second, the elevator failed and jammed at the 1.5 degree position, and the elevator angle 
u Se continued to stay at the 1.5 degree position throughout the simulation. Unlike the nominal controller K n , the 
reconfigured controller was specifically designed to address the loss of control authority and the persistent 
disturbance issues arising in the elevator jam scenario. Right after K t replaced K (] . the new controller wasted no 
time to step up the only available control input, the thrust u r , to allow the power level P to swing between 15.5 
percent and -8.3 percent as shown in the upper left figure. Note that the controller was able to manage the loss of 
elevator control and to neutralize the effect of the persistent disturbance caused by the elevator jam. As shown in 
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the upper left figure, the altitude went down with an 80% undershoot and a 20% overshoot, then settled towards 
the desired altitude at -50 ft after t=20s. 



Figure 9. Time response for Part 1, Case 3. 


Part 2: Ascending Maneuver of the GTM Aircraft with Altitude Tracking Controller 

The simulations in Part 2 are similar to that in Part 1, but the maneuver is ascending instead of descending and the 
elevator jam is assumed to occur at a different time, and therefore the jam position will be different. We will observe 
how the elevator jam affects the response of different maneuvers and verify that the same fixed reconfigured 
controller K t is capable of handling elevator jams at a variety of locations as long as the remaining control input has 
enough control authority. The GTM aircraft is assumed to be flying at the trim condition at t=0, when it is 
commanded to ascend 30 feet from its current altitude, 600 feet. To follow the command, the nominal controller K 0 
will start to maneuver the aircraft to fly toward the desired altitude via the control of the thrust u T and the elevator 
u Se . Three simulation cases for this ascending maneuver will be considered in the following. 





Figure 10. Time response for Part 2, Case 1. 
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Case 1: No failure occurs and the nominal controller K 0 will continue to finish the control of ascending. 

The simulation results for Case 1 are shown in Figure 10. The bottom left and right figures reveal how the 
elevator and thrust were controlled to affect the pitch rate, pitch angle and the angle of attack (in the upper right 
figure) that in turn would determine the altitude and velocity shown in the upper left figure. It can be seen that the 
altitude h went up from 0 (the trim altitude 600 ft) to overshoot a little bit and quickly settle at the desired altitude, 
30 ft (actual altitude = 630 ft) around t=10s, while the velocity V decreased from 0 (the trim velocity 127 ft/s) to - 
8 ft/s (119 ft/s) at t=5s and then up to -3 ft/s (124 ft/s) at t=20s. In the altitude tracking process, the thrust increase 
was less than 3 percent and the elevator operating range was between -3 deg and 0.3 deg. 






Figure 11. Time response for Part 2, Case 2. 






Figure 12. Time response for Part 2, Case 3. 


Case 2: Elevator jam occurs at t=1.5s, but no failure accommodation action is taken. 

The simulation results for Case 2 are shown in Figure 11. The aircraft behaved exactly the same as Case 1 before 
the elevator failed. To follow the ascent command, the nominal controller K 0 dictated the elevator to move down 
to -2.9 deg position and then to reverse to go towards the trim condition. At 1.5 second, the elevator failed and 
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jammed at the -0.34 deg position. Although the jam position was only a small deviation from the trim condition, 
the accumulated effect of the persistent disturbance it produced would continue to increase as time went by. As 
shown in the bottom left figure, the elevator angle u Se continued to stay at the -0.34 deg position throughout the 
simulation. The elevator failure rendered the elevator control signal from the nominal controller K 0 useless, and 
the elevator jam position at -0.34 deg would produce an unwanted persistent rotational moment to cause the 
aircraft to pitch up. It can be seen in the bottom right figure that the inadequate controller K 0 straggled to use the 
only available control input, the engine thrust u T , to prevent the aircraft from further pitching up. However, it 
only causes the aircraft to pitch down and up with large amplitude, oscillating between 13 ft and 55 ft, and there 
was no sign of settling towards the desired altitude as shown in the upper left and right figures of Figure 11. 

Case 3: Elevator jam occurs at t=1.5s, and the reconfigured controller K x steps in to replace K 0 at t=1.6s. 

The simulation results for Case 3 are shown in Figure 12. The aircraft behaved the same as Cases 1 and 2 before 
the elevator failed. At the 1.5 second mark, the elevator failed and jammed at the -0.34 degree position, and the 
elevator angle u Se continued to stay at the -0.34 degree position throughout the simulation. Unlike the nominal 
controller K 0 , the reconfigured controller K t was specifically designed to address the loss of control authority 
and the persistent disturbance issues arising in the elevator jam scenario. Right after K x replaced K 0 at t=1.6s, the 
new controller quickly decreased the only available control input, the thrust u T , to -5 percent and then swung up 
to 5 percent as shown in the bottom right figure. Note that the controller was able to effectively use the remaining 
control to neutralize the effect of the persistent disturbance caused by the elevator jam. As shown in the upper left 
figure, the altitude went up with a 50% overshoot and a 20% undershoot, then settled at the desired altitude at 30 
ft after t=20s. 

The above simulations have shown that the same fixed reconfigured controller K\ was able to accommodate 
two elevator jams at different jam positions 1.5 degree and -0.34 degree and achieve altitude tracking using just one 
thrust control input with strict constraints. In principle, the single fixed reconfigured controller K x would be capable 
of accommodating elevator jams at arbitrary jam positions within operating range if the available thrust control has 
enough control authority. In reality, the thrust control power is limited. For the GTM aircraft example considered in 
the paper, at the trim the thrust control input is 15% of its maximum possible thrust. The mathematical model used 
was obtained from the linearization around the trim, and therefore 0 thrust control input actually means 15% of the 
maximum possible thrust, and the thrust control input constraint for the above simulation should be between -15% 
and +85%. 


V. Conclusions 

In this paper, we have employed the longitudinal flight dynamics model of the NASA GTM unmanned aircraft 
to demonstrate the simplicity and effectiveness of the proposed actuator jam failure accommodation approach based 
on controller switching, servomechanism, and //, control theory. The single fixed reconfigured optimal controller 
specifically designed for the elevator jam scenario was capable of neutralizing the effect of the persistent 
disturbance caused by the impaired elevator jammed at any position in the operating range as long as the only 
available control input, the engine thrust control, has enough power. The proposed hybrid, servomechanism and 
H 1 control approach can be extended to the cases involving multiple actuator failures, structure damage failures, 
subsystem failures, etc. using just a limited number of reconfigured controllers. Furthermore, these reconfigured 
controllers can be also nonlinear, robust, and adaptive so that the control system can handle nonlinearities, plant 
uncertainties, uncertain disturbances, and parameter dependencies, etc. 
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